windscribe
Releases1
Last Release
security holding package
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| >= 2.10.1, <= 2.17.10, = 2.18.1, = 2.18.3, = 2.18.5 | 7.8 HIGH | — | ||
A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to execute arbitrary commands as root via the 'adapterName' parameter of the 'changeMTU' function. Fixed in Windscribe v2.18.3-alpha and v2.18.8. | ||||